Administration

Table Of Contents
Prerequisites
If users select remote desktops by using VMware Identity Manager, verify that VMware Identity
Manager is installed and configured for use with Connection Server and that Connection Server is
paired with a SAML 2.0 Authentication server.
Procedure
1 In Horizon Administrator, select View Configuration > Servers.
2 On the Connection Servers tab, select a Connection Server instance and click Edit.
3 Configure use of the Blast Secure Gateway.
Option Description
Enable the Blast Secure Gateway Select Use Blast Secure Gateway for Blast connections to machine
Enable the Blast Secure Gateway for
HTML Access
Select Use Blast Secure Gateway for only HTML Access Blast connections
to machine
Disable the Blast Secure Gateway Select Do not use Blast Secure Gateway
The Blast Secure Gateway is enabled by default.
4 Click OK to save your changes.
Off-load TLS Connections to Intermediate Servers
Horizon Client must use HTTPS to connect to Horizon 7. If your Horizon clients connect to
load balancers or other intermediate servers that pass on the connections to Connection Server
instances or security servers, you can off-load TLS to the intermediate servers.
Import TLS Off-loading Servers' Certificates to Horizon 7 Servers
If you off-load TLS connections to an intermediate server, you must import the intermediate
server's certificate onto the Connection Server instances or security servers that connect to
the intermediate server. The same TLS server certificate must reside on both the off-loading
intermediate server and each off-loaded Horizon 7 server that connects to the intermediate server.
If you deploy security servers, the intermediate server and the security servers that connect to
it must have the same TLS certificate. You do not have to install the same TLS certificate on
Connection Server instances that are paired to the security servers and do not connect directly to
the intermediate server.
If you do not deploy security servers, or if you have a mixed network environment with some
security servers and some external-facing Connection Server instances, the intermediate server
and any Connection Server instances that connect to it must have the same TLS certificate.
If the intermediate server's certificate is not installed on the Connection Server instance or security
server, clients cannot validate their connections to Horizon 7. In this situation, the certificate
thumbprint sent by the Horizon 7 server does not match the certificate on the intermediate server
to which Horizon Client connects.
Horizon 7 Administration
VMware, Inc. 44